<p>This study proposes a human-AI collaboration to model the landscape of cyber threat intelligence (CTI) and use it to detect suspicious communication indicating impending cybersecurity incidents. We show how the collaboration between cybersecurity experts and AI-based text-classification methods develops an understanding of professional hackers and helps detect cybersecurity threats more accurately. The human-AI collaboration rests on a Reciprocal Human–Machine Learning (RHML) model, in which a human expert and a machine interact repeatedly over time and simultaneously continually learn to detect professional hackers. Two cybersecurity experts employed qualitative data analysis and worked with RHML software assistance to classify 6651 messages from an online hackers’ forum. We discovered an improvement, over time, of both the detection accuracy and the experts’ understanding of the threat landscape as represented by their concept maps. In particular, the concept map refers to the hacker’s capabilities, intent, and behaviour to define the threat landscape needed for professional detection, in contrast to amateur hackers. We believe this approach may ultimately lead to a more robust and proactive cybersecurity posture and translate into operational advantages in the field of CTI.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Human–AI Enhancement of Cyber Threat Intelligence

  • Daniel Cohen,
  • Dov Te’eni,
  • Inbal Yahav,
  • Alexey Zagalsky,
  • David Schwartz,
  • Gahl Silverman,
  • Yossi Mann,
  • Amir Elalouf,
  • Jeremy Makowski

摘要

This study proposes a human-AI collaboration to model the landscape of cyber threat intelligence (CTI) and use it to detect suspicious communication indicating impending cybersecurity incidents. We show how the collaboration between cybersecurity experts and AI-based text-classification methods develops an understanding of professional hackers and helps detect cybersecurity threats more accurately. The human-AI collaboration rests on a Reciprocal Human–Machine Learning (RHML) model, in which a human expert and a machine interact repeatedly over time and simultaneously continually learn to detect professional hackers. Two cybersecurity experts employed qualitative data analysis and worked with RHML software assistance to classify 6651 messages from an online hackers’ forum. We discovered an improvement, over time, of both the detection accuracy and the experts’ understanding of the threat landscape as represented by their concept maps. In particular, the concept map refers to the hacker’s capabilities, intent, and behaviour to define the threat landscape needed for professional detection, in contrast to amateur hackers. We believe this approach may ultimately lead to a more robust and proactive cybersecurity posture and translate into operational advantages in the field of CTI.